Import table
advapi32.dll
TraceMessage, EqualSid, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegGetValueW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, LookupAccountSidW, ConvertSidToStringSidW, LookupAccountNameW, CreateWellKnownSid, GetLengthSid, CopySid, ConvertStringSidToSidW, FreeSid, AllocateAndInitializeSid, LogonUserW, RegCreateKeyExW, RegDeleteKeyW, RegDeleteValueW, RegEnumKeyExW, RegEnumValueW, CheckTokenMembership, CloseServiceHandle, OpenServiceW, OpenSCManagerW, ControlService, QueryServiceStatus, ChangeServiceConfigW, IsValidSid, IsWellKnownSid, EventWrite
crypt32.dll
CryptProtectData, CryptUnprotectData
fwpuclnt.dll
FwpmSubLayerDeleteByKey0, FwpmEngineOpen0, FwpmTransactionBegin0, FwpmEngineClose0, FwpmTransactionCommit0, FwpmTransactionAbort0, FwpmFilterDeleteByKey0, FwpmCalloutDeleteByKey0
gdi32.dll
DeleteObject, GetStockObject, GetObjectW, CreateSolidBrush, GetDeviceCaps, BitBlt, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, DeleteDC
gdiplus.dll
GdiplusStartup, GdipCloneImage, GdipCreateHBITMAPFromBitmap, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromFile, GdipDisposeImage, GdipAlloc, GdipFree, GdiplusShutdown
kernel32.dll
FlushInstructionCache, GetCurrentProcess, lstrcmpW, MulDiv, GlobalUnlock, GlobalLock, GlobalAlloc, SetLastError, HeapSetInformation, SetDllDirectoryW, GlobalFree, LoadLibraryW, MultiByteToWideChar, lstrlenA, GlobalHandle, HeapFree, GetProcessHeap, HeapAlloc, HeapReAlloc, FormatMessageW, CreateFileW, GetTempPathW, GetLocaleInfoW, GetSystemTimeAsFileTime, GetProcAddress, FreeLibrary, GetThreadUILanguage, WideCharToMultiByte, CreateThread, SetThreadPriority, TlsGetValue, TlsSetValue, GetModuleHandleW, GetTickCount, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, InterlockedIncrement, InterlockedDecrement, GetCurrentThreadId, InitializeSRWLock, AcquireSRWLockShared, ReleaseSRWLockShared, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, EnterCriticalSection, LeaveCriticalSection, LocalFree, GetLastError, ProcessIdToSessionId, GetCurrentProcessId, InterlockedExchange, InitializeConditionVariable, Sleep, WaitForSingleObject, WakeAllConditionVariable, SleepConditionVariableSRW, SystemTimeToFileTime, GetComputerNameW, CompareFileTime, CloseHandle, GetProcessId, GetModuleFileNameW, OpenProcess, lstrlenW, RaiseException, InitializeCriticalSection, DeleteCriticalSection, CompareStringW, HeapDestroy, HeapSize, InterlockedCompareExchange, LoadLibraryA, IsProcessorFeaturePresent, GetTickCount64, GetFileAttributesW, CreateMutexW, IsWow64Process, GetVersionExW, VirtualUnlock, VirtualLock, TrySubmitThreadpoolCallback, CallbackMayRunLong, CreateThreadpool, SetThreadpoolThreadMinimum, SetThreadpoolThreadMaximum, CloseThreadpool, ConvertFiberToThread, WaitForMultipleObjectsEx, OpenThread, QueueUserAPC, IsThreadAFiber, TlsFree, TlsAlloc, ResetEvent, SetEvent, CreateEventW, LocalAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, VirtualFree, VirtualAlloc, GetStartupInfoW, SetUnhandledExceptionFilter, ReleaseMutex
msvcr90.dll
DllMain
netapi32.dll
NetUserGetLocalGroups, NetLocalGroupAddMembers, NetUserDel, NetUserAdd, NetApiBufferFree, NetGetJoinInformation, NetUserEnum
ole32.dll
CoInitializeSecurity, CLSIDFromProgID, CLSIDFromString, CoTaskMemAlloc, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoCreateGuid, CoTaskMemFree, CoSetProxyBlanket, CoCreateInstance, CoUninitialize, CoInitializeEx, CoAllowSetForegroundWindow, StringFromGUID2, OleLockRunning, CoGetClassObject
secur32.dll
GetUserNameExW
shell32.dll
SHAppBarMessage, CommandLineToArgvW, Shell_NotifyIconW, FindExecutableW, ShellExecuteW, SHGetKnownFolderPath, ShellExecuteExW, SHFileOperationW, SHGetFolderPathW
shlwapi.dll
UrlCanonicalizeA, PathCombineW, PathFileExistsW, PathAppendW, StrRChrW
user32.dll
SetWindowLongW, GetWindowLongW, AttachThreadInput, PostQuitMessage, GetForegroundWindow, SetProcessDefaultLayout, SetFocus, SetForegroundWindow, GetSysColor, CharNextW, GetClientRect, ClientToScreen, ScreenToClient, GetDC, ReleaseDC, InvalidateRect, InvalidateRgn, RedrawWindow, UnregisterClassA, SetCapture, IsChild, GetParent, GetDlgItem, GetClassNameW, ReleaseCapture, FillRect, CallWindowProcW, EndPaint, BeginPaint, GetDesktopWindow, DestroyAcceleratorTable, GetWindow, GetFocus, RegisterWindowMessageW, GetClassInfoExW, RegisterClassExW, CreateWindowExW, CreateAcceleratorTableW, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, CloseClipboard, FindWindowW, OpenClipboard, GetKeyState, PtInRect, GetCursorPos, ShowWindow, UpdateLayeredWindow, EndDialog, MapDialogRect, SendDlgItemMessageW, SetWindowContextHelpId, GetMonitorInfoW, MonitorFromWindow, DialogBoxIndirectParamW, EmptyClipboard, CallNextHookEx, SetWindowsHookExW, UnhookWindowsHookEx, AppendMenuW, DestroyMenu, CreatePopupMenu, TrackPopupMenu, UnregisterClassW, IsIconic, ChangeWindowMessageFilter, LoadIconW, MsgWaitForMultipleObjects, IsWindowUnicode, GetMessageW, GetMessageA, TranslateMessage, DispatchMessageW, DispatchMessageA, PeekMessageW, AllowSetForegroundWindow, DestroyIcon, SendMessageW, SystemParametersInfoW, MoveWindow, GetWindowRect, SetWindowPos, SetTimer, PostMessageW, SetClipboardData, GetWindowThreadProcessId, KillTimer, DefWindowProcW, LoadCursorW, IsWindow, DestroyWindow, SetCursor
uxcore.dll
DllMain
wininet.dll
InternetCrackUrlA, InternetCreateUrlA
wlidux.dll
WlidUxInitProcess, WlidUxUninitProcess, WlidUxCreateObject
wtsapi32.dll
WTSUnRegisterSessionNotification, WTSRegisterSessionNotification, WTSFreeMemory, WTSEnumerateSessionsW, WTSQuerySessionInformationW